# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Harness Authentication Settings API version: 1.0.0 extends: openapi/harness-authentication-settings-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 23 - target: $.paths['/ng/api/authentication-settings/ldap/settings'].get update: x-apievangelist-phrasing: intent: View the account's LDAP settings effect: read questions: - What LDAP connection and sync settings are configured on my Harness account? - Can I see the user and group queries our current LDAP setup uses? instructions: - text: Show the LDAP settings configured for account {account}. slots: account: query.accountIdentifier - text: Pull up our current LDAP configuration and its sync details. method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/ldap/settings'].put update: x-apievangelist-phrasing: intent: Change the account's existing LDAP settings effect: write questions: - Can I change the cron schedule of an LDAP sync that's already set up? - How do I edit the group query in my existing LDAP configuration? instructions: - text: Update existing LDAP setting {identifier} on account {account} to sync on cron {cron}. slots: identifier: requestBody.identifier account: query.accountIdentifier cron: requestBody.cronExpression - text: Rename our existing LDAP setting {identifier} to {display_name}. slots: identifier: requestBody.identifier display_name: requestBody.displayName method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/ldap/settings'].post update: x-apievangelist-phrasing: intent: Set up LDAP authentication for the account effect: write questions: - What do I need to connect my account to an LDAP directory for the first time? - Can a brand-new LDAP configuration include both user and group queries? instructions: - text: Create a new LDAP setting named {display_name} with identifier {identifier} on account {account}. slots: display_name: requestBody.displayName identifier: requestBody.identifier account: query.accountIdentifier - text: Set up LDAP for our account using connection settings {connection}. slots: connection: requestBody.connectionSettings method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/ldap/settings'].delete update: x-apievangelist-phrasing: intent: Remove the account's LDAP settings effect: destructive questions: - Can I remove the LDAP configuration from my account entirely? - Is there a way to tear down the LDAP integration on an account? instructions: - text: Delete the LDAP settings on account {account}. slots: account: query.accountIdentifier - text: Remove our LDAP configuration completely. method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/delete-saml-metadata'].delete update: x-apievangelist-phrasing: intent: Delete the account-level SAML metadata effect: destructive questions: - How do I wipe the SAML metadata for my whole account? - Can I clear the account-level SAML configuration without naming a specific SSO id? instructions: - text: Delete the account-level SAML metadata for account {account}. slots: account: query.accountIdentifier - text: Clear all SAML metadata on our account. method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/saml-metadata/{samlSSOId}/delete'].delete update: x-apievangelist-phrasing: intent: Delete one SAML SSO configuration's metadata effect: destructive questions: - Can I remove the metadata for just one of several SAML identity providers? - Which call deletes a single SAML SSO setting by its id? instructions: - text: Delete the SAML metadata for SAML SSO id {saml_sso_id}. slots: saml_sso_id: path.samlSSOId - text: Remove SAML SSO configuration {saml_sso_id} from account {account}. slots: saml_sso_id: path.samlSSOId account: query.accountIdentifier method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/saml-metadata-upload/{samlSSOId}/authentication'].put update: x-apievangelist-phrasing: intent: Turn login on or off for one SAML setting effect: write questions: - Can I temporarily disable sign-in through one SAML provider without deleting it? - How do I switch a specific SAML SSO setting back on for authentication? instructions: - text: Set authentication enabled to {enable} for SAML setting {saml_sso_id}. slots: enable: query.enable saml_sso_id: path.samlSSOId - text: Disable SAML login for SSO setting {saml_sso_id} on account {account}. slots: saml_sso_id: path.samlSSOId account: query.accountIdentifier method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings'].get update: x-apievangelist-phrasing: intent: Get the account's authentication settings effect: read questions: - Which login mechanisms and authentication settings does my account use? - Can I check which auth mechanism is currently active using the original settings endpoint? instructions: - text: Show the authentication settings for account {account}. slots: account: query.accountIdentifier - text: Fetch our account's current login configuration from the original endpoint. method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/v2'].get update: x-apievangelist-phrasing: intent: Get version 2 of the account's auth settings effect: read questions: - Is there a newer v2 response for account authentication settings? - Where do I read the version 2 authentication settings for an account? instructions: - text: Get the v2 authentication settings for account {account}. slots: account: query.accountIdentifier - text: Fetch the version 2 authentication settings view for our account. method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/login-settings/password-strength'].get update: x-apievangelist-phrasing: intent: Check the account's password strength policy effect: read questions: - What password strength rules are enforced for users on my account? - Does our account require a minimum password complexity? instructions: - text: Show the password strength policy for account {account}. slots: account: query.accountIdentifier - text: Tell me our password complexity requirements. method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/saml-login-test'].get update: x-apievangelist-phrasing: intent: Test SAML connectivity for the whole account effect: read questions: - Can I verify the account's SAML sign-in is reachable before rolling it out? - Is there a way to run a SAML login test at the account level? instructions: - text: Run a SAML connectivity test for account {account_id}. slots: account_id: query.accountId - text: Test whether our account-wide SAML login works. method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/saml-login-test/{samlSSOId}'].get update: x-apievangelist-phrasing: intent: Test connectivity for one SAML SSO setting effect: read questions: - When I have several SAML providers, can I test sign-in for just one of them? - Which call tests a specific SAML SSO configuration by its id? instructions: - text: Test SAML connectivity for SSO setting {saml_sso_id}. slots: saml_sso_id: path.samlSSOId - text: Run a login test against SAML configuration {saml_sso_id} on account {account}. slots: saml_sso_id: path.samlSSOId account: query.accountIdentifier method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/oauth/remove-mechanism'].delete update: x-apievangelist-phrasing: intent: Remove OAuth sign-in from the account effect: destructive questions: - Can I turn off OAuth sign-in for my whole account? - How do I delete the OAuth settings configured for our account? instructions: - text: Remove the OAuth login mechanism from account {account}. slots: account: query.accountIdentifier - text: Delete our OAuth sign-in settings. method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/public-access'].put update: x-apievangelist-phrasing: intent: Enable or disable account-level public access effect: write questions: - Can I allow public access to resources at the account level? - Where do I switch off public access for my account? instructions: - text: Toggle public access for account {account}. slots: account: query.accountIdentifier - text: Turn off account-level public access. method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/session-timeout-account-level'].put update: x-apievangelist-phrasing: intent: Set the user session timeout for the account effect: write questions: - Can I log users out automatically after a period of inactivity? - Is there an absolute session limit I can set in addition to the idle timeout? instructions: - text: Set the session timeout for account {account} to {minutes} minutes. slots: account: query.accountIdentifier minutes: requestBody.sessionTimeOutInMinutes - text: Set idle session timeout to {minutes} minutes and absolute timeout to {absolute_minutes} minutes. slots: minutes: requestBody.sessionTimeOutInMinutes absolute_minutes: requestBody.absoluteSessionTimeOutInMinutes method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/two-factor-admin-override-settings'].put update: x-apievangelist-phrasing: intent: Enforce two-factor authentication account-wide effect: write questions: - Can an admin require two-factor authentication for every user on the account? - How do I override users' 2FA choices at the account level? instructions: - text: Set the admin two-factor override on account {account} to {enabled}. slots: account: query.accountIdentifier enabled: requestBody.adminOverrideTwoFactorEnabled - text: Turn on enforced two-factor authentication for all our users. method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/update-auth-mechanism'].put update: x-apievangelist-phrasing: intent: Switch the account's active login mechanism effect: write questions: - Can I change which authentication mechanism users sign in with? - Which setting makes SAML or LDAP the active login method for the account? instructions: - text: Change the authentication mechanism for account {account} to {mechanism}. slots: account: query.accountIdentifier mechanism: query.authenticationMechanism - text: Make {mechanism} our active login method. slots: mechanism: query.authenticationMechanism method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/oauth/update-providers'].put update: x-apievangelist-phrasing: intent: Choose which OAuth providers users can sign in with effect: write questions: - Can I limit which OAuth identity providers are allowed for login? - What's the way to update the list of allowed OAuth sign-in providers? instructions: - text: Set the allowed OAuth providers for account {account} to {providers}. slots: account: query.accountIdentifier providers: requestBody.allowedProviders - text: Update our OAuth provider allowlist to {providers}. slots: providers: requestBody.allowedProviders method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/saml-metadata-upload'].put update: x-apievangelist-phrasing: intent: Update the account's existing SAML metadata effect: write questions: - How do I replace the metadata file on our existing account-level SAML configuration? - Can I change the group membership attribute on the current SAML setup? instructions: - text: Replace the SAML metadata on account {account_id} with file {file}. slots: account_id: query.accountId file: requestBody.file - text: Update the logout URL of our existing SAML configuration to {logout_url}. slots: logout_url: requestBody.logoutUrl method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/saml-metadata-upload'].post update: x-apievangelist-phrasing: intent: Upload SAML metadata to add a SAML provider effect: write questions: - What do I need to upload to set up a new SAML identity provider? - Can I enable just-in-time user provisioning when adding a SAML provider? instructions: - text: Upload SAML metadata file {file} for account {account_id} with display name {display_name}. slots: file: requestBody.file account_id: query.accountId display_name: requestBody.displayName - text: Add a new SAML provider named {friendly_name} with JIT provisioning set to {jit}. slots: friendly_name: requestBody.friendlySamlName jit: requestBody.jitEnabled method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/saml-metadata-upload/{samlSSOId}'].put update: x-apievangelist-phrasing: intent: Update one SAML SSO configuration's metadata effect: write questions: - How can I update the metadata for one specific SAML SSO id when several exist? - Can I rotate the client secret on a particular SAML configuration? instructions: - text: Update SAML configuration {saml_sso_id} with metadata file {file}. slots: saml_sso_id: path.samlSSOId file: requestBody.file - text: Change the display name of SAML setting {saml_sso_id} to {display_name}. slots: saml_sso_id: path.samlSSOId display_name: requestBody.displayName method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/whitelisted-domains'].put update: x-apievangelist-phrasing: intent: Update the account's allowed login domains effect: write questions: - Can I restrict sign-in to users from specific email domains? - Where do I change the whitelisted domains for my account? instructions: - text: Update the whitelisted domains for account {account}. slots: account: query.accountIdentifier - text: Replace our allowed sign-in domain list. method: generated generated: '2026-09-26' - target: $.paths['/ng/api/authentication-settings/saml-metadata'].post update: x-apievangelist-phrasing: intent: Upload SAML metadata via the alternate endpoint effect: write questions: - Is there a second endpoint for uploading SAML metadata besides saml-metadata-upload? - Can I post SAML metadata through the /saml-metadata path instead? instructions: - text: Upload SAML metadata file {file} for account {account_id} through the alternate saml-metadata endpoint. slots: file: requestBody.file account_id: query.accountId - text: Use the /saml-metadata endpoint to add SAML provider type {provider_type}. slots: provider_type: requestBody.samlProviderType method: generated generated: '2026-09-26'